🇺🇸
TPI-Abuse
2026-09-08 02:58:27
(13 minutes ago)
(mod_security) mod_security (id:210492) triggered by 35.231.0.76 (76.0.231.35.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 35.231.0.76 (76.0.231.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 22:58:23.234783 2026] [security2:error] [pid 17390:tid 17390] [client 35.231.0.76:4896] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.kaldaragroup.com"] [uri "/@fs/app/.env"] [unique_id "ap95z4-HxFRkDqUpg11buAAAAGQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
Hazzard
2026-09-08 02:51:34
(20 minutes ago)
(apache-useragents) Failed apache-useragents trigger with match [redacted]): (CF_ENABLE)
Bad Web Bot
🇺🇸
TPI-Abuse
2026-09-08 02:38:14
(33 minutes ago)
(mod_security) mod_security (id:210492) triggered by 35.231.0.76 (76.0.231.35.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 35.231.0.76 (76.0.231.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 22:38:07.543729 2026] [security2:error] [pid 31212:tid 31212] [client 35.231.0.76:17868] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.sunsettrailsardmore.com"] [uri "/@fs/root/.env"] [unique_id "ap91D5aj78TNcJ--nwSS7wAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇰
HostingGroup
2026-09-08 02:31:53
(40 minutes ago)
Automated malicious activity (Honeypot Trap) detected and blocked at the CDN edge by NordicCDN Shiel ...
show more
Automated malicious activity (Honeypot Trap) detected and blocked at the CDN edge by NordicCDN Shield. Offenses: 10. First blocked: 2026-09-08.
show less
Bad Web Bot
Web App Attack
🇩🇪
ghostwarriors
2026-09-08 02:20:18
(51 minutes ago)
Webpage scraping
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-08 02:00:00
(1 hour ago)
Aggressive web scan
Web App Attack
Anonymous
2026-09-08 01:54:05
(1 hour ago)
$f2bV_matches
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 01:53:20
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 35.231.0.76 (76.0.231.35.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 35.231.0.76 (76.0.231.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 21:53:12.681741 2026] [security2:error] [pid 14367:tid 14367] [client 35.231.0.76:43578] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ftp.jeffstamper.com"] [uri "/@fs/../.env"] [unique_id "ap9qiHac_LbL5MyV0rRH0QAAAE0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇧🇪
cmbplf
2026-09-08 01:40:34
(1 hour ago)
575 requests with url.path *credentials.json
Brute-Force
Bad Web Bot
🇺🇸
TPI-Abuse
2026-09-08 01:33:04
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 35.231.0.76 (76.0.231.35.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 35.231.0.76 (76.0.231.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 21:32:57.008040 2026] [security2:error] [pid 3014:tid 3014] [client 35.231.0.76:29748] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "styxfreeworld.grayhost.net"] [uri "/@fs/.env"] [unique_id "ap9lybMt3EM5pInofa_5dAAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 01:13:09
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 35.231.0.76 (76.0.231.35.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 35.231.0.76 (76.0.231.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 21:13:06.001361 2026] [security2:error] [pid 26375:tid 26375] [client 35.231.0.76:40150] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "certifiedfarmersmarkets.org"] [uri "/@fs/.env.production"] [unique_id "ap9hItIq05N0sZfroVlasQAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-08 01:10:44
(2 hours ago)
Malicious activity detected
DDoS Attack
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 00:57:33
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.231.0.76 (76.0.231.35.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 35.231.0.76 (76.0.231.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 20:57:28.417324 2026] [security2:error] [pid 3712:tid 3712] [client 35.231.0.76:63748] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.timjbutler.com"] [uri "/@fs/root/.env"] [unique_id "ap9deD4572pnzgeKjfr4VAAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇷🇴
iulianh
2026-09-08 00:46:44
(2 hours ago)
80,443
Brute-Force
SSH
🇺🇸
TPI-Abuse
2026-09-08 00:30:22
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.231.0.76 (76.0.231.35.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 35.231.0.76 (76.0.231.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 20:30:14.185240 2026] [security2:error] [pid 2900:tid 2900] [client 35.231.0.76:65448] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.terrysavastano.com"] [uri "/@fs/root/.env"] [unique_id "ap9XFi_fSlDtL8bcTwDmmAAAABo"]
show less
Brute-Force
Bad Web Bot
Web App Attack